Questa potrebbe essere la soluzione?
Codice PHP:
$orderby = white_list($_GET['orderby'], ["position"], "Invalid field name");
$direction = white_list($_GET['direction'], ["ASC","DESC"], "Invalid ORDER BY direction");
$protQuery=$slide_query->prepare("SELECT * FROM `pictures` ORDER BY `$orderby` $direction");
if ($protQuery->execute($_POST[‘position’])); {
$risultato = $protQuery->fetchAll(\PDO::FETCH_ASSOC);}
$slide_result = new PDO($dsn,$user,$pass,array($slide_query));
while($slide_sql = $slide_query->fetch_all(PDO::FETCH_ASSOC));